Security and privacy
Information should always be protected, in whatever format and however it is shared, communicated or stored
At Simacan, we work with critical information assets which are crucial for our business, for maintaining our clients’ trust and for safeguarding the future of our services. Here, we explain how we protect these assets – and we outline Simacan’s information security commitments to our employees, our current and future clients and our suppliers.
I am...
new to Simacan
How do we keep your information safe and our processes secure?
Read more about: Information Security Management System (ISMS)
Privacy and the GDPR
Also see: Simacan’s Privacy Policy
Where and how do we store your data?
Read more about: Amazon Web Services (AWS)
Compliance and the data processing agreement
To safeguard these security measures and ensure compliance with the relevant current legislation, we have drafted a data processing agreement (DPA) based on experience and sound legal advice. As Simacan’s customer, supplier or partner, you can make use of this DPA.
What does this mean when using Simacan’s services?
We understand that our clients rely on the Simacan Control Tower in their primary business functions. We are committed to making the Simacan Control Tower a highly available product you can count on. The Simacan cloud infrastructure runs on fault-tolerant systems, and the Simacan Support Team is available to quickly resolve any production problems and incidents. All Simacan clients who have an SLA contract in place benefit from the Simacan Support Team’s services, 24/7 and 365 days a year.
Read more about:
Incident management & response
Simacan Support Team
And the software?
All new features, functionalities and design changes go through an information security review process. In addition, all Simacan source code is extensively tested and manually peer-reviewed prior to being deployed to production. Simacan employees work closely with one another to resolve any additional security concerns that may arise during development, e.g. by introducing features (such as single sign-on) which enhance the security of our services. In addition to the security checks during development, additional checks are also carried out throughout the year, e.g. a vulnerability scan which is performed by an external party.
Read more about:
External security audits
Simacan user
How do we keep your information safe and our processes secure?
To ensure the secure processing of data, we have implemented several measures to protect our clients’ data, our suppliers’ data and, of course, our own data. All of these security measures are part of our ISO/IEC 27001-certified Information Security Management System (ISMS).
Read more about:
Information Security Management System
Where and how do we store your data?
Data encryption
Multi-factor authentication (MFA)
In addition to data encryption, we have implemented two-factor authentication for all server access across our production environment. Moreover, Simacan’s entire office networking infrastructure is configured according to industry best practices. For Simacan employees, this means they are required to set up two-factor authentication on all the accounts where client data is processed or stored.
Read more about:
Amazon Web Services
What does this mean when using Simacan’s services?
We understand that our clients rely on the Simacan Control Tower in their primary business functions. We are committed to making the Simacan Control Tower a highly available product you can count on. The Simacan cloud infrastructure runs on fault-tolerant systems, and the Simacan Support Team is available to quickly resolve any production problems and incidents. All Simacan clients who have an SLA contract in place benefit from the Simacan Support Team’s services, 24/7 and 365 days a year.
Read more about:
Incident management & response
Simacan Support Team
And the software?
All new features, functionalities and design changes go through an information security review process. In addition, all Simacan source code is extensively tested and manually peer-reviewed prior to being deployed to production. Simacan employees work closely with one another to resolve any additional security concerns that may arise during development, e.g. by introducing features (such as single sign-on) which enhance the security of our services. In addition to the security checks during development, additional checks are also carried out throughout the year, e.g. a vulnerability scan which is performed by an external party.
Read more about:
External security audits
The role of our Simacan employees
Every Simacan employee must be aware of the significance of the information being handled and ensure that proper controls are applied to prevent unauthorized disclosure of or loss/lack of accessibility to the information.
Simacan employees are required to read Simacan’s Information Security Policy. They also have to agree to include a formal acknowledgement of information security practices as an addendum to their employment contract. The policy covers the security, availability and confidentiality of the Simacan Information Security Management System. Awareness of information security risks and the available controls to mitigate them is promoted in annual training sessions for all employees.
Read more about:
Confidentiality
end customer
Privacy and the GDPR
Besides processing customer/business data, we also work with personal data such as clients’ email addresses, drivers’ phone numbers and locations, employees’ contact details, etc.
We take privacy very seriously, and we only process information in accordance with relevant legislation: the General Data Protection Regulation (GDPR). Furthermore, we only process data within the borders of the EU. We have implemented several security measures specifically to protect your data from data leaks, hacks and other unwanted events.
Where and how do we store your data?
Also see: Simacan’s Privacy Policy
Simacan support team
Information Security Management System
Incident management response
External security audits
Confidentiality
Amazon Web Services
Contact us
Contact us at security@simacan.com